CVE-2026-102600: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as proto or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Node.js process to crash and resulting in denial of service. Applications that do not use @socket.io/cluster-engine are not affected. This issue is fixed in version 0.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@socket.io/cluster-engineto a version that resolves this vulnerability.Fixed in 0.1.1
Event History
Frequently Asked Questions
Which deployments are affected?
Only applications using @socket.io/cluster-engine in a clustered Socket.IO deployment are affected. Applications that do not use @socket.io/cluster-engine are not affected.
What does an attacker need to exploit this issue?
An attacker can exploit the issue remotely without authentication or user interaction by supplying a specially named session ID, such as __proto__ or constructor. Successful exploitation can crash the Node.js process and cause denial of service.
What version fixes the issue?
Upgrade @socket.io/cluster-engine to version 0.1.1 or later. Versions prior to 0.1.1 are affected.